Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry. User must upgrade to 0.9.2.
CVSS
No CVSS.
References
Configurations
No configuration.
History
31 Dec 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-31 16:15
Updated : 2024-12-31 16:15
NVD link : CVE-2024-56802
Mitre link : CVE-2024-56802
CVE.ORG link : CVE-2024-56802
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization